XML 72 R37.htm IDEA: XBRL DOCUMENT v3.25.0.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2024
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
We maintain processes for assessing, identifying and managing material risks from cybersecurity threats.
We regularly use both outsourced and in-house information security expertise to employ a variety of administrative, technical, and physical data safeguards designed to both deter and mitigate cybersecurity risks, including cyber incident response procedures, endpoint threat detection and response solutions, employee training, third-party risk reviews, penetration testing, technical control reviews, vulnerability assessments, and enterprise-wide risk assessments. These policies and procedures, which are based on the National Institute of Standards and Technology framework, align with international standards under ISO/IEC 27001 and are reviewed annually, including via an annual assessment of relevant IT SOX controls and Payment Card Industry Data Security Standard reviews performed both by external Qualified Security Assessors and authorized members of our internal information security team. Our third-party due diligence processes also include procedures for identifying cybersecurity threats associated with third-party service providers. Cybersecurity risks are also identified and evaluated through our enterprise risk management (ERM) processes, which are overseen by the Audit Committee of our Board of Directors. Through our ERM processes, key stakeholders across the business identify, assess, and manage risk, including material cybersecurity risks. These processes enable us to monitor and assess the evolving landscape of cybersecurity risks.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] We maintain processes for assessing, identifying and managing material risks from cybersecurity threats.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block] The Audit Committee of our Board of Directors oversees risks associated with information technology and cybersecurity.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] Chief Digital and Innovation Officer (CDIO) and Vice President (VP) of Platforms, Infrastructure and Cybersecurity
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
Our information security program is administered under the supervision of our EVP, Chief Digital and Innovation Officer (CDIO) and Vice President (VP) of Platforms, Infrastructure and Cybersecurity, who share responsibility for assessing and managing the Company’s cybersecurity risks. Both our CDIO and VP of Platforms, Infrastructure, and Cybersecurity have over 20 years of related experience, holding technical leadership roles at notable multinational organizations, across diverse industries.
Our CDIO and VP of Platforms, Infrastructure and Cybersecurity also monitor the prevention, detection, mitigation and remediation of cybersecurity incidents through the same processes described above for the identification and management of material cybersecurity risks.
The Audit Committee of our Board of Directors oversees risks associated with information technology and cybersecurity. Cybersecurity risks and incidents identified through these processes are evaluated by our CDIO and VP of Platforms, Infrastructure and Cybersecurity. Our VP of Platforms, Infrastructure and Cybersecurity provides regular updates on a quarterly basis, and more frequently as required, on these matters to the Audit Committee of our Board of Directors. Such reports may include discussions on current control audits, risk assessments, proposed mitigation measures, and other key information technology and cyber initiatives.
Cybersecurity Risk Role of Management [Text Block] Cybersecurity risks are also identified and evaluated through our enterprise risk management (ERM) processes, which are overseen by the Audit Committee of our Board of Directors. Through our ERM processes, key stakeholders across the business identify, assess, and manage risk, including material cybersecurity risks. These processes enable us to monitor and assess the evolving landscape of cybersecurity risks.
Our information security program is administered under the supervision of our EVP, Chief Digital and Innovation Officer (CDIO) and Vice President (VP) of Platforms, Infrastructure and Cybersecurity, who share responsibility for assessing and managing the Company’s cybersecurity risks. Both our CDIO and VP of Platforms, Infrastructure, and Cybersecurity have over 20 years of related experience, holding technical leadership roles at notable multinational organizations, across diverse industries.
Our CDIO and VP of Platforms, Infrastructure and Cybersecurity also monitor the prevention, detection, mitigation and remediation of cybersecurity incidents through the same processes described above for the identification and management of material cybersecurity risks.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] The Audit Committee of our Board of Directors oversees risks associated with information technology and cybersecurity.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] Both our CDIO and VP of Platforms, Infrastructure, and Cybersecurity have over 20 years of related experience, holding technical leadership roles at notable multinational organizations, across diverse industries.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] The Audit Committee of our Board of Directors oversees risks associated with information technology and cybersecurity. Cybersecurity risks and incidents identified through these processes are evaluated by our CDIO and VP of Platforms, Infrastructure and Cybersecurity. Our VP of Platforms, Infrastructure and Cybersecurity provides regular updates on a quarterly basis, and more frequently as required, on these matters to the Audit Committee of our Board of Directors. Such reports may include discussions on current control audits, risk assessments, proposed mitigation measures, and other key information technology and cyber initiatives.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true